CVE-2023-41069: Use After Free
Accessibility. This issue was addressed with improved redaction of sensitive information.
Other sources
Airport. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
App Store. The issue was addressed with improved handling of protocols.
— Apple
Apple Neural Engine. A use-after-free issue was addressed with improved memory management.
— Apple
Apple Neural Engine. An out-of-bounds read was addressed with improved input validation.
— Apple
Apple Neural Engine. The issue was addressed with improved handling of caches.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40529
- CVE-2023-40384
- CVE-2023-40448
- CVE-2023-40432
- CVE-2023-41174
- CVE-2023-40409
- CVE-2023-40412
- CVE-2023-42871
- CVE-2023-41071
- CVE-2023-40399
- CVE-2023-40410
- CVE-2023-42872
- CVE-2023-42925
- CVE-2023-38612
- CVE-2023-32361
- CVE-2023-41232
- CVE-2023-35984
- CVE-2023-41065
- CVE-2023-38596
- CVE-2023-40420
- CVE-2023-40528
- CVE-2023-32396
- CVE-2023-41069
- CVE-2023-41980
- CVE-2023-40395
- CVE-2023-40431
- CVE-2023-40391
- CVE-2023-40441
- CVE-2023-40434
- CVE-2023-40396
- CVE-2023-41995
- CVE-2023-42870
- CVE-2023-41974
- CVE-2023-41981
- CVE-2023-41984
- CVE-2023-40429
- CVE-2023-41060
- CVE-2023-40400
- CVE-2023-40454
- CVE-2023-41073
- CVE-2023-40403
- CVE-2023-40427
- CVE-2023-42957
- CVE-2023-41068
- CVE-2023-41986
- CVE-2023-40401
- CVE-2023-42949
- CVE-2023-40456
- CVE-2023-40520
- CVE-2023-42934
- CVE-2023-41063
- CVE-2023-40422
- CVE-2023-35990
- CVE-2023-40417
- CVE-2023-40452
- CVE-2023-41070
- CVE-2023-40419
- CVE-2023-40428
- CVE-2023-41968
- CVE-2023-40424
- CVE-2023-39434
- CVE-2023-40414
- CVE-2023-41074
- CVE-2023-35074
- CVE-2023-32359
- CVE-2023-40385
- CVE-2023-42833
- CVE-2023-38610
- CVE-2023-42969
- CVE-2023-42961
- CVE-2023-40393
- CVE-2023-42977
- CVE-2023-42973
- CVE-2023-38614
- CVE-2023-42970
- CVE-2023-42875
Frequently Asked Questions
What is the severity of CVE-2023-41069?
CVE-2023-41069 is considered a high severity vulnerability due to its potential to allow unauthorized authentication using 3D models.
How do I fix CVE-2023-41069?
To fix CVE-2023-41069, update to iOS 17 or iPadOS 17, which include improved Face ID anti-spoofing measures.
Which devices are affected by CVE-2023-41069?
CVE-2023-41069 affects devices running iOS versions below 17 and iPadOS versions below 17.
What type of vulnerability is CVE-2023-41069?
CVE-2023-41069 is an authentication vulnerability related to Face ID that can be exploited with 3D models.
Does CVE-2023-41069 require action from users?
Yes, users must take action to update their devices to mitigate the risks associated with CVE-2023-41069.